---
cve: "CVE-2026-103604"
severity: "HIGH"
cvss: 8.7
epss: "0.3%"
vendor: "Legion of the Bouncy Castle Inc."
kev: false
exploited: false
published: "2026-10-02 08:17:00"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-05T05:18:14+02:00"
---

# CVE-2026-103604

> 8.7 HIGH · 🧪 PoC

## Beschreibung

Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUtilities.ValueToString) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service through CPU exhaustion via a certificate, CRL, certification request or other structure whose name contains a long attribute value made up of characters that must be escaped, such as commas, or of leading or trailing spaces, because each escaping backslash was inserted into the buffer being scanned, so the work grew quadratically with the length of the value. Applications are exposed when they convert such a name to a string, for example to log or display it, or compare it with IetfUtilities.RdnAreEqual, as PKIX path validation does for directoryName name constraints.

## CNA-Record (Kanon, cvelistV5)

- CNA: **bcorg**
- State: PUBLISHED
- Stand: 2026-10-02 17:44:20
- CNA-CVSS: **8.7** (`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- 4007498b13582d90ee1eda5d9920c324428b98b3 (Commit)
- bd03e38bbb49db5be33f4463fc40997400c545cc (Commit)

## BSI-Hinweise (deutsch)

- [Bouncy Castle: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3713) — _BSI-Einstufung: mittel_
  Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Bouncy Castle ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand auszulösen.

## Referenzen

- <https://github.com/bcgit/bc-csharp/wiki/CVE-2026-103604>
- <https://github.com/bcgit/bc-csharp/commit/bd03e38bbb49db5be33f4463fc40997400c545cc>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-103604) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
